BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Jul 2014 | Easy Call srlEasy Call srl was fined EUR 112,000 by the Garante for making unsolicited promotional calls. The company contacted individuals listed in the opposition register, breaching data protection rules. | IT | Garante | GDPR | €112,000 | ↗ |
| 14 Jun 2018 | Faiella Nicola s.r.l.Faiella Nicola s.r.l. was fined EUR 112,000 by the Garante for improper processing of personal data using geolocation and video surveillance systems. The authority found that the company did not comply with data protection requirements when deploying these tools. | IT | Garante | GDPR | €112,000 | ↗ |
| 21 Mar 2013 | Giant s.r.l.Giant s.r.l. was fined 114,000 EUR by the Garante for the unauthorized registration of numerous phone cards to third parties without their knowledge. The authority found this conduct to be in breach of data protection rules. | IT | Garante | GDPR | €114,000 | ↗ |
| 30 Nov 2023 | Dane anonimowe (L. Sp. z o.o. z siedzibą we W.)UODO imposed an administrative fine of PLN 117,900 on L. Sp. z o.o. for failing to implement appropriate technical and organizational measures proportionate to the risk of data processing. The authority found deficiencies in ensuring system availability, resilience, and the ability to quickly restore access to personal data after a physical or technical incident. | PL | UODO | GDPR | €27,110 | ↗ |
| 11 May 2020 | Hälso- och sjukvårdsnämnden i Region Örebro länHälso- och sjukvårdsnämnden i Region Örebro län was fined by IMY 120,000 SEK for publishing sensitive personal data on its website without a legal basis. The authority found breaches of GDPR Articles 5, 6, 9, and 32. | SE | IMY | GDPR | €11,321 | ↗ |
| 27 May 2021 | Azienda Usl della RomagnaAzienda Usl della Romagna was fined by the Garante in the amount of EUR 120,000 for violations related to the processing of a patient's health data in the gynecology department. The case also involved issues with electronic health records and data breaches. | IT | Garante | GDPR | €120,000 | ↗ |
| 06 Jun 2024 | Cappello Giovanni & figli s.r.l.Cappello Giovanni & figli s.r.l. was fined by Garante for unlawful processing of employee personal data using Infinity DMS software and X.-Face 380 hardware. The authority found that the company's practices breached GDPR principles. | IT | Garante | GDPR | €120,000 | ↗ |
| 26 Oct 2011 | H3G S.p.A.H3G S.p.A. was fined EUR 120,000 by the Garante for sending unsolicited promotional communications to a fixed telephone line. The conduct breached data protection provisions. | IT | Garante | GDPR | €120,000 | ↗ |
| 02 Oct 2025 | TIGER MEDIA INC.TIGER MEDIA INC. was fined by the AEPD EUR 120,000 for processing personal data without a lawful basis. The authority also found that the company failed to appoint an EU representative, in breach of GDPR Articles 6 and 27. | ES | AEPD | GDPR | €120,000 | ↗ |
| 05 Jul 2019 | VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined €120,000 by the AEPD for failing to exercise due diligence in response to a fraudulent situation involving unauthorized service contracts. The authority found a breach of Article 6 GDPR. | ES | AEPD | GDPR | €120,000 | ↗ |
| 08 Jun 2023 | Maxen Power Supply LimitedMaxen Power Supply Limited used overseas call centres to make unsolicited marketing calls to businesses. The conduct breached regulations 21 and 24 of PECR, and the ICO imposed a fine of 120,000 GBP and issued an enforcement notice. | GB | ICO | ePrivacy | €139,000 | ↗ |
| 15 Jan 2026 | Allay Claims Ltd The ICO issued an MPN and EN to Allay Claims Ltd after a large volume of unsolicited SMS messages promoting PPI tax refund services. The case indicates a breach of direct marketing and electronic communications rules. | GB | ICO | GDPR | €138,000 | ↗ |
| 12 Dec 2024 | Money Bubble Ltd MPNBetween October and November 2022, the company made 168,852 spam calls, leading to further complaints to the ICO and TPS. Money Bubble Ltd MPN did not provide evidence that the called individuals had consented to receive calls. The ICO imposed a £120,000 fine. | GB | ICO | GDPR | €145,000 | ↗ |
| 14 Dec 2017 | Salvatore AloiSalvatore Aloi was fined EUR 120,000 by the Italian Garante. The case concerned the processing of personal data of 12 individuals without consent, by activating phone cards in their names without authorization. | IT | Garante | GDPR | €120,000 | ↗ |
| 27 May 2021 | Tempocasa S.p.A.Tempocasa S.p.A. was fined €120,000 by the Italian Garante. The authority found that the company made unsolicited promotional calls without the required consent, breaching GDPR rules on data processing and consent. | IT | Garante | GDPR | €120,000 | ↗ |
| 12 Apr 2012 | Alitalia – Compagnia Aerea Italiana s.p.a.Alitalia was fined by the Garante for inadequate data protection measures and for failing to provide proper information to customers during call center interactions. The authority found that these practices breached Italian data protection law. | IT | Garante | GDPR | €120,000 | ↗ |
| 15 Oct 2024 | Quick Tax Claims LimitedThe ICO found that Quick Tax Claims Limited sent 7,863,547 unlawful text messages over one month, generating 66,793 complaints. In 93% of complaints, recipients said there was no opt-out option, and the company had bought personal data from suppliers without valid consent. | GB | ICO | GDPR | €143,000 | ↗ |
| 01 Jan 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 120,000 EUR for a data protection breach involving unauthorized SIM card duplication. The incident enabled fraudulent activity, and the authority found that the company had not implemented sufficient preventive measures. | ES | AEPD | GDPR | €120,000 | ↗ |
| 31 Mar 2021 | Anonymizováno (ÚOOÚ UOOU-04077/20-13)The entity was fined for processing personal data from public registers without a legal basis and for failing to respond to a data subject's erasure request. The case highlights deficiencies in lawful processing and in handling data subject rights. | CZ | UOOU | GDPR | €4,590 | ↗ |
| 21 Mar 2024 | Regione LazioThe Garante fined Regione Lazio EUR 120,000 for inadequate security measures that led to attempted unauthorized access to user accounts. The authority found a breach of GDPR requirements on data protection and processing security. | IT | Garante | GDPR | €120,000 | ↗ |